Complete static archive of GigaTap articles about VPN, privacy, OPSEC, and security.
- CVE-2018-25236: When the Management Plane Betrays You - NVD rates a Hirschmann HiOS/HiSecOS web management auth bypass critical, proving exposed admin interfaces are live attack surface.
- Dirty Frag: Public Linux Root PoC Before Patch Clarity - A public Linux local root PoC raises risk because the chain is reported as reliable, deterministic, and not yet clearly patched.
- Docker and Black Duck target container CVE noise - Docker says Black Duck can identify Docker Hardened Images, use VEX data, and suppress base-image findings marked not affected. The value is cleaner triage
- Enterprise AI Agents in 2026: A Deployment Checklist, Not a Demo - Zapier argues AI agents are now an enterprise expectation—but only if they ship with scoped permissions, audit logs, human approvals, and guardrails. Here’
- EU Cloud Breach Probe: IAM Is the Blast Radius - The European Commission cloud breach probe is a reminder that IAM, keys, trust chains, and logs decide cloud incident damage.
- Ivanti EPMM zero-day RCE: patch fast, audit admin access - Ivanti says CVE-2026-6973 is being exploited as a zero-day against on-prem EPMM and requires admin authentication. What’s known, what’s not, and the practi
- Ollama bug can leak memory from exposed AI servers - A critical Ollama out-of-bounds read can leak process memory from network-exposed servers, including keys, prompts, and user data. The same report also des
- OpenAI Breach Shows the Real Risk in Trusted Build Pipelines - OpenAI says two employee devices were breached in the TanStack-linked supply-chain campaign. The larger issue is how trusted CI/CD and package release path
- Pentagi shows where AI pentest agents are heading - Pentagi is an open-source autonomous penetration testing project. The useful question is not hype, but fit, scope control, and what teams must verify before use.
- PoC-in-GitHub refreshed: the diff is the only safe signal - A new auto-update in PoC-in-GitHub is a visibility signal, not a vulnerability report. The commit timestamp is real; the security meaning depends on the diff.
- Privacy and rights signals: 4 short updates worth checking - 4 short source updates grouped into one practical GigaTap site note.
- SAP npm packages hit by Bun-based stealer - Snyk reports malicious SAP CAP npm releases with a Bun-based credential stealer and worm-capable npm propagation code. Observed spread was limited, but the
- Teams vishing is back — and it can be a state-backed cover story - Rapid7 described a Teams-driven intrusion attributed to MuddyWater: screen-sharing to harvest credentials, MFA manipulation, and persistence via remote too
- Trane Tracer Flaws: Root Access in the Building Core - CISA warns high-risk Trane Tracer flaws can enable root compromise, auth bypass, and DoS in exposed building controllers.
- Utah’s Digital ID Has a Loyalty Problem - Utah frames digital ID as modernization, but the real issue is who the system is built to serve when access and control collide.
- ValueCell brings AI agents to finance. Verify before trust - ValueCell is a Python-based open-source platform for financial AI agents. The repository has strong GitHub interest, but metadata alone does not prove safe
- VPN Subscription Safety Checklist for Mobile Networks - A safe checklist for evaluating VPN and VLESS subscription feeds before importing them into mobile clients.
- A new Mindstorms app could keep older LEGO kits useful - Mindstorms Robot Creator is a new F-Droid submission for older LEGO robotics kits. It aims to keep Mindstorms hardware usable with local code generation, h
- ABC’s FCC Fight Is a First Amendment Test - ABC’s pushback against FCC pressure could test whether broadcasters resist regulatory jawboning or self-censor to avoid a fight.
- Age Gates Are Becoming Speech Control - California’s social media ban debate shows how age verification can become a privacy and free-speech control layer.
- agenticSeek looks useful. Check the trust model first - A practical checklist for evaluating Fosowl/agenticSeek before giving a local autonomous agent access to files, browsers, code, or credentials.
- ClickFix is back, and Vidar Stealer is the payload - Australia’s ACSC says an ongoing campaign is using ClickFix social engineering to spread Vidar Stealer. The main risk is not novelty. It is user-driven com
- Cloudflare’s Token Controls Expose the Real IAM Problem - Cloudflare’s new API and OAuth controls point to a bigger issue: machine credentials stay dangerous when least privilege is optional.
- Genkit Middleware gives AI agents a control layer - Google’s Genkit Middleware adds hooks around generation, models, and tools so developers can build retries, fallbacks, and human approvals into agentic AI